Episode 198: AI Privacy from a Risk-Based Perspective

 

 

In episode 198 of Cybersecurity Where You Are, Sean Atkinson discusses artificial intelligence (AI) and privacy from a risk-based cybersecurity perspective. Together, he explores how organizations and individuals can assess AI risk, apply governance frameworks, evaluate third-party AI services, and balance innovation with due diligence.

Here are some highlights from our episode:

  • 00:41. Framing the conversation around AI, privacy, and risk-based controls
  • 02:22. Due diligence and ethical considerations around AI products and services
  • 03:14. Data minimization and transparency as foundations for AI privacy
  • 04:46. Privacy impact assessments as a way to understand AI data collection and use
  • 05:42. AI governance and the tension between implementation velocity and risk management
  • 10:08. The use of existing data flows and controls in AI assessments
  • 11:57. Algorithmic transparency and the challenge of understanding AI decision making
  • 13:47. Standards, frameworks, and data sovereignty in AI privacy governance
  • 15:12. Encryption, anonymization, tokenization, and federated learning as privacy safeguards
  • 16:40. The need to shift stakeholder input left in AI development and deployment lifecycles
  • 19:13. Building literacy around security, data management, privacy, and AI risk
  • 23:40. The value of cross-functional and written assessment criteria for AI risk
  • 26:21. A call to action for keeping pace with AI privacy and and innovation risk

Resources

If you have some feedback or an idea for an upcoming episode of Cybersecurity Where You Are, let us know by emailing [email protected].

As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.